Data circulation method and device of integrated platform and finance and tax integrated platform
Through the data flow method of the integrated platform, the coordinated work of RPA, CL, iPaaS and data security monitoring modules is used to solve the problems of multi-source heterogeneous data integration and data flow in traditional financial processing, and the efficient and secure flow of financial data is achieved, which significantly improves financial processing efficiency and data security.
Patent Information
- Application Number
- CN202510502860.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-22
AI Technical Summary
There are difficulties in integrating multi-source heterogeneous data in traditional financial processing, data flow between systems relies on manual intervention or simple interface calls, and the lack of a unified data security flow mechanism, resulting in inefficient information islands and financial management.
Provide a data flow method of an integrated platform, including RPA module, CL module, iPaaS module and data security monitoring module. Through the coordinated work of these modules, the structured transformation of multi-source data, the classification and sorting of financial information and the determination of processing sequence, and the identification and encryption of risk data and key data are ensured to ensure the safe flow of data between systems.
It realizes seamless data exchange and collaborative work between multiple business processing systems, significantly improves financial processing efficiency, reduces the risk of human error, enhances data security, and solves the problems of multi-source heterogeneous data integration and data flow in traditional financial processing.
Smart Images

Figure CN120013262A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of data transmission, and in particular to a data flow method and device for an integrated platform and an integrated finance and taxation platform. Background Art
[0002] With the rapid development of the digital economy, corporate financial management is undergoing unprecedented changes. The traditional financial processing model relies on a large number of manual operations, which is not only inefficient but also prone to human errors. Under the wave of global digitalization, financial process automation has become a key factor in improving the core competitiveness of enterprises. Especially in a complex and changing economic environment, enterprises need to process financial data more accurately and efficiently to support the strategic planning and business development of decision-makers.
[0003] Financial data is multi-source, complex and sensitive. Financial data generated in daily business operations comes from a wide range of sources, including but not limited to ERP systems, CRM systems, electronic invoice platforms, bank statements, supplier systems and other channels. These data formats vary, including structured data, semi-structured data and unstructured data, such as PDF invoices, scanned documents, emails, etc. In addition, financial data often contains sensitive information, such as bank account numbers, tax numbers, customer information, etc., and data security issues are particularly prominent.
[0004] In recent years, Robotic Process Automation (RPA) technology has been widely used in the financial field, helping enterprises to automate some processes. By simulating human operations, RPA can perform highly repetitive and rule-based tasks, such as data entry and report generation. However, enterprises usually have multiple business processing systems, and the data flow between these systems often relies on manual intervention or simple interface calls. There is a lack of a unified data security flow mechanism, resulting in prominent information island problems. Therefore, although a single RPA technology can automate basic processes, it is relatively limited in achieving cross-system data security flow, resulting in a significant reduction in financial management efficiency. Summary of the invention
[0005] The embodiments of the present application provide a data flow method and device for an integrated platform and a finance and taxation integrated platform, which are used to effectively improve financial management efficiency and realize secure data flow between systems.
[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions: In the first aspect, a data flow method for an integrated platform is provided, which is applied to a finance and taxation integrated platform. The finance and taxation integrated platform is obtained by integrating n business processing platforms. The finance and taxation integrated platform includes an RPA module, a CL module, an iPaaS module, and a data security monitoring module. The method includes: The RPA module responds to the multi-source data entry instruction, converts the multi-source data into structured data, and identifies the financial information in the structured data; The RPA module classifies and sorts the financial information and determines the processing order of the classified and sorted financial information; The CL module analyzes the financial information according to the processing sequence, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy; The iPaaS module receives risk data and key data, and transfers the risk data and key data to the data security monitoring module; The data security monitoring module uses a first processing strategy to conduct risk screening on risk data, and uses a second processing strategy to encrypt key data; and The data security monitoring module transfers risk data and encrypted key data to the corresponding business processing platform.
[0007] In a possible implementation manner of the first aspect, the CL module generates the first processing strategy and the second processing strategy, including: The CL module extracts contextual features of financial information and obtains historical data; The CL module dynamically generates a first processing strategy and a second processing strategy based on context features and historical data; The first processing strategy includes a risk data classification mechanism, a risk assessment model, an abnormal data identification rule and a risk data tracing mechanism. The risk data classification mechanism is used to determine the risk level of risk data. The risk assessment model is used to determine the risk probability of risk data according to the risk level of risk data. The abnormal data identification rule is used to determine the abnormal data in risk data according to the risk probability. The risk data tracing mechanism is used to record the processing flow of risk data. The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy and data desensitization processing rules. The hierarchical encryption strategy is used to determine the sensitivity of key data and determine the corresponding encryption algorithm based on the sensitivity. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a dispersed manner. The access permission control strategy is used to set data access permissions. The data desensitization processing rules are used to mask or replace sensitive fields in key data.
[0008] In another possible implementation manner of the first aspect, the CL module dynamically generates the first processing strategy and the second processing strategy based on the context feature and the historical data, including: The CL module inputs data features and context features as input parameters into the pre-built machine learning model to analyze and obtain the historical processing records of risk data and the historical encryption records of key data; The CL module determines the parameters and conditions of the first processing strategy based on the historical processing records, and applies the parameters and conditions of the first processing strategy to the first processing strategy, wherein the parameters and conditions of the first processing strategy include the threshold parameters of the risk data classification mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rules, and the record items of the risk data tracing mechanism; The CL module determines the parameters and conditions of the second processing strategy based on the historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy, wherein the parameters and conditions of the second processing strategy include the encryption strength of the hierarchical encryption strategy, the key update cycle of the dynamic key management mechanism, the permission matrix of the access permission control strategy, and the desensitization method of the data desensitization processing rules.
[0009] In another possible implementation of the first aspect, the RPA module classifies and sorts the financial information, and determines a processing order of the classified and sorted financial information, including: The RPA module divides the financial information based on preset data categories to obtain at least one financial data set; The RPA module determines the correlation between each financial data set and other financial data sets, and merges the financial data sets with higher correlation than a preset correlation to obtain at least one correlated financial data set; For any associated financial data set, the RPA module uses preset scoring rules to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set, where the total score is the sum of the time sensitivity score and the data value score. The order of the total scores from high to low is used as the processing order of the associated financial data sets.
[0010] In another possible implementation of the first aspect, the CL module includes a basic data layer, a business logic layer, and a risk control layer, and the CL module determines risk data and key data of financial information, including: For each associated financial data set, at the basic data layer, the CL module performs format verification on the associated financial data set and treats the data in the associated financial data set that fails the format verification as risk data; At the business logic layer, the CL module verifies the business logic consistency of the associated financial data set, and treats the data in the associated financial data set that fails the business logic consistency verification as risk data; At the risk control layer, the CL module performs data sensitivity verification on the associated financial data set and regards the data in the associated financial data set that fails the data sensitivity verification as key data.
[0011] In another possible implementation manner of the first aspect, after the iPaaS module receives the risk data and the key data, the method further includes: The iPaaS module extracts the first feature of the risk data and the second feature of the key data, and determines the optimal data flow path based on the first feature and the second feature; The iPaaS module monitors the efficiency and quality of the optimal data flow path in real time; The iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path.
[0012] In another possible implementation of the first aspect, the efficiency of the optimal data flow path is characterized by network delay and bandwidth occupancy, the quality of the optimal data flow path is characterized by data packet loss rate, and the iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path, including: The iPaaS module uses a pre-built adaptive adjustment model to calculate the optimal combination of data transmission compression rate and encryption strength based on network latency, bandwidth occupancy, and packet loss rate to balance data security and transmission efficiency for the optimal data flow path.
[0013] In another possible implementation manner of the first aspect, the method further includes: The data security monitoring module uploads risk data and encrypted key data to the blockchain network, which is used to verify the integrity and compliance of risk data and key data based on smart contracts.
[0014] In a second aspect, the present application provides an electronic device, including: a memory configured to store instructions; and The processor is configured to call the instructions from the memory and implement the above-mentioned integrated platform data flow method when executing the instructions.
[0015] On the third aspect, the present application provides an integrated finance and taxation platform, which is deployed in the above-mentioned electronic device and is used to execute the operating steps of the data flow method of the integrated platform.
[0016] Through the above technical solution, it is possible to respond to multi-source data entry instructions, convert heterogeneous data from multiple channels such as ERP system, CRM system, electronic invoice platform, bank statement and supplier system, including structured data, semi-structured data and unstructured data, into structured data, and identify the financial information therein, solving the problem of difficulty in integrating multi-source heterogeneous data in traditional financial processing; the CL module analyzes the financial information according to the determined processing order, identifies risk data and key data, and dynamically generates targeted first processing strategy and second processing strategy according to data characteristics, enhancing the intelligent processing capability of complex financial data; the iPaaS module receives risk data and key data as an integration platform, and securely transfers them to the data security monitoring module, effectively solving the limitation that the data flow between traditional systems relies on manual intervention or simple interface calls, and eliminating the problem of information islands; the data security monitoring module uses the first processing strategy to risk check the risk data and the second processing strategy to encrypt the key data, providing security protection for sensitive information in the financial data; the data security monitoring module transfers the risk data and encrypted key data that have been risk checked to the corresponding business processing platform, realizing secure data flow across systems. Through the collaborative process, not only the limitations of single RPA technology in processing complex financial data are overcome, but also an end-to-end data security flow mechanism is built through the introduction of iPaaS modules and data security monitoring modules, enabling enterprises to achieve seamless data exchange and collaborative work between multiple business processing systems under the premise of ensuring data security, significantly improving financial processing efficiency, reducing the risk of human errors, and enhancing data security. Compared with traditional solutions that rely on manual operations or single RPA technology, this technical solution realizes the automation and intelligence of the entire process of financial data from entry, analysis, flow to secure processing through the collaborative work of multiple modules.
[0017] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 A flow chart of a data flow method of an integrated platform provided in an embodiment of the present application; Figure 2 A schematic diagram of the structure of a financial and tax integration platform provided in an embodiment of the present application; Figure 3 A schematic diagram of RPA module data processing provided in an embodiment of the present application; Figure 4 A schematic diagram of a CL module risk analysis provided in an embodiment of the present application; Figure 5 A module interaction timing diagram provided in an embodiment of the present application; Figure 6 A schematic diagram of a risk assessment model provided in an embodiment of the present application; Figure 7 A dynamic key management flow chart provided for an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the specific implementation methods described herein are only used to illustrate and explain the embodiments of the present application, and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0020] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back...), such directional indications are only used to explain the relative position relationship, movement status, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0021] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or suggesting their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0022] Figure 1 The following is a schematic diagram showing a flow chart of a data transfer method of an integrated platform according to an embodiment of the present application. Figure 1 As shown, an embodiment of the present application provides a data flow method for an integrated platform, which is applied to a finance and taxation integrated platform. The finance and taxation integrated platform is integrated from n business processing platforms. The finance and taxation integrated platform includes an RPA module, a CL module, an iPaaS module, and a data security monitoring module. The method may include the following steps.
[0023] S110, the RPA module responds to the multi-source data input instruction, converts the multi-source data into structured data, and identifies financial information in the structured data; S120, the RPA module classifies and sorts the financial information, and determines the processing order of the classified and sorted financial information; S130, the CL module analyzes the financial information according to the processing sequence, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy; S140, the iPaaS module receives the risk data and the key data, and transfers the risk data and the key data to the data security monitoring module; S150, the data security monitoring module uses the first processing strategy to perform risk screening on risk data, and uses the second processing strategy to encrypt key data; and S160. The data security monitoring module transfers the risk data and encrypted key data to the corresponding business processing platform.
[0024] Figure 2 A schematic diagram of the structure of a financial and tax integration platform provided in an embodiment of the present application is shown. Figure 2 As shown in the figure, in the data flow process of the integrated finance and taxation platform, the RPA (Robotic Process Automation) module first responds to the multi-source data entry instructions to achieve standardized data conversion and financial information identification. Multi-source data refers to various types of financial-related data from different business systems and channels, including but not limited to Excel reports exported from the ERP system, customer transaction records in the CRM system, electronic invoices in PDF format, scanned paper document images, bank statements, settlement documents in the supplier system, and financial attachments in emails. Multi-source data includes structured database records, semi-structured Excel tables, and unstructured PDF documents and image files.
[0025] Data entry instructions can be scheduled tasks, manually triggered by users, or API calls from other systems. After receiving the instructions, the RPA module will call the corresponding data collection components according to the data source type, such as database connectors, file readers, OCR (optical character recognition) engines, etc. For structured data such as database records or Excel tables in standard formats, the RPA module directly extracts data through field mapping; for semi-structured data such as non-standard Excel tables or XML files, template matching and rule parsing are used to extract valid information; for unstructured data such as PDF documents or scanned images, OCR technology is used to digitize the text content, and then natural language processing technology is used to extract key information.
[0026] To understand the time sequence and collaborative relationship between the RPA module, CL module, iPaaS module, and data security monitoring module in data flow, please refer to Figure 5 ,like Figure 5As shown in the figure, during the data conversion process, the RPA module first unifies the format of the original data, such as date format standardization, numerical format standardization, and text format standardization. Text format standardization can remove redundant spaces and special characters. Then, data quality checks can be further performed, including null value detection, outlier identification, and logical consistency verification, to mark or automatically correct problematic data. Finally, the cleaned data is converted into a unified structured format such as JSON or XML to ensure the consistency and integrity of the data structure.
[0027] After completing the data structured conversion, the RPA module further identifies the financial information in the structured data. Financial information identification adopts a method that combines the rule engine and machine learning. The rule engine performs preliminary identification based on predefined financial field features (such as keywords such as "amount", "tax rate", "invoice number", etc.) and format features (such as the numerical format of the amount and the character pattern of the invoice number). The machine learning model can identify more complex financial information patterns by learning from historical data, such as the structural characteristics of different types of invoices, the organizational logic of various financial statements, etc. In addition, in this embodiment, for specific industries and business scenarios, the RPA module also integrates professional vocabulary libraries and business rule libraries to further improve the accuracy and completeness of financial information identification.
[0028] After completing the structured conversion of multi-source data and the identification of financial information, the RPA module classifies and sorts the financial information. The classification and sorting process first divides the identified financial information into different categories according to the preset financial information classification system. The financial information classification system usually includes but is not limited to the following dimensions: classification by business type (such as sales business, procurement business, expense reimbursement, asset management, etc.); classification by document type (such as invoices, contracts, bank statements, reports, etc.); classification by amount level (such as major amounts, general amounts, small amounts, etc.); classification by timeliness (such as emergency processing, routine processing, periodic processing, etc.); preliminary classification by risk level (such as high risk, medium risk, low risk).
[0029] The classification process can adopt a multi-level classification algorithm. Specifically, the preliminary classification is first carried out through keyword matching and pattern recognition, and then refined classification is carried out in combination with context information and business rules. For example, for a financial record, first identify whether it contains keywords such as "invoice" and "receipt" to determine the document type, then determine the amount level based on the amount value, and analyze the date information in the record to determine the timeliness. Finally, comprehensively consider information such as counterparties and business descriptions to preliminarily assess the risk level.
[0030] After completing the basic classification, the RPA module further analyzes the relationship between financial information and identifies related financial data sets. The relationship analysis can be based on the following factors: business relationship (such as different links of the same business); time relationship (such as related transactions within the same time period); counterparty relationship (such as multiple transactions with the same customer or supplier); amount relationship (such as records with consistent amounts or clear calculation relationships); document relationship (such as the relationship between invoices and corresponding contracts and orders). The correlation calculation uses a weighted scoring model to assign different weights to different correlation factors and calculate the correlation strength between financial information. When the correlation strength exceeds the preset threshold, these financial information are merged into one processing unit to ensure that related financial data can be processed together to avoid business logic errors caused by fragmented processing.
[0031] After determining the classification and association of financial information, the RPA module calculates the processing priority of each group of financial information according to the preset scoring rules, thereby determining the final processing order. The scoring rules can consider one or more of the following factors: timeliness factors (such as deadlines, statutory reporting deadlines, etc.); importance factors (such as amount, business importance, etc.); risk factors (such as preliminary risk ratings, abnormal indicators, etc.); resource consumption factors (such as processing complexity, required approval levels, etc.); dependency factors (such as whether there are pre-processing requirements).
[0032] In this embodiment, the determination of the processing order can also follow the principles of system load balancing and maximizing processing efficiency. The RPA module can dynamically monitor the system resource usage, and while ensuring the timely processing of high-priority tasks, reasonably arrange the execution time of medium and low-priority tasks to avoid uneven peaks and valleys in system resources. In addition, for financial information with similar processing flows, the RPA module is arranged to process continuously, reducing the additional overhead caused by switching processing modes and improving overall processing efficiency.
[0033] After the RPA module completes the classification and sorting of financial information and determines the processing order, the CL (cognitive learning) module takes over the subsequent financial information analysis work. The CL module is the core intelligent analysis component of the financial and tax integration platform. It is responsible for in-depth analysis of financial information, identifying risk data and key data, and generating corresponding processing strategies in a targeted manner. The CL module analyzes financial information one by one in strict accordance with the processing order determined by the RPA module to ensure that high-priority financial data is processed in a timely manner.
[0034] Financial information analysis adopts a multi-level verification architecture, which conducts comprehensive verification at the basic data layer, business logic layer, and risk control layer. The basic data layer verification mainly checks the integrity, consistency, and accuracy of the data, such as whether the required fields are complete, whether the values are within a reasonable range, and whether the date format is correct. The business logic layer verification focuses on whether the financial data complies with business rules and process requirements, such as whether the purchase order matches the invoice amount, whether the expense reimbursement meets the budget limit, and whether the payment information is consistent with the contract terms. The risk control layer verification evaluates from the perspective of compliance and risk prevention and control, such as whether the transaction complies with tax law requirements, whether there are abnormal transaction patterns, and whether sensitive counterparties are involved.
[0035] On the basis of multi-level verification, risk data identification adopts a combination of rule engine and machine learning model. The rule engine conducts preliminary screening based on preset risk identification rules, such as abnormal amount (outside the historical transaction range), abnormal time (non-working hours transaction), abnormal frequency (frequent transaction in a short period of time), abnormal counterparty (new or sensitive counterparty), etc. The machine learning model establishes a benchmark model of normal transaction mode by learning from historical transaction data. Any transaction that deviates from this benchmark is marked as a potential risk. In addition, the CL module can also integrate external data sources, such as corporate credit database, tax anomaly list, industry risk warning information, etc., to further improve the accuracy and comprehensiveness of risk identification.
[0036] At the same time, the CL module can also identify key data in financial information, that is, data that has a significant impact on the company's financial status, tax compliance and business operations. Key data identification is based on a data sensitivity assessment model that comprehensively considers factors such as the business importance of the data (such as core financial indicators, key performance indicators, etc.), compliance importance (such as data required for tax returns, audit focus data, etc.), security sensitivity (such as bank account numbers, tax numbers, customer information, etc.) and data integrity requirements (such as data that needs to maintain a complete audit chain). Through the sensitivity scoring mechanism, the system marks data that exceeds the preset threshold as key data, which requires special protection and processing.
[0037] Based on the identification results of risk data and key data, the CL module further generates corresponding processing strategies. The first processing strategy targets risk data, and mainly includes risk data classification mechanism, risk assessment model, abnormal situation identification rules and risk tracing mechanism. Risk data classification divides risk data into three levels: high, medium and low. Different levels use different processing procedures and approval authorities. The risk assessment model calculates the risk score based on the risk factor weights and gives risk handling suggestions. The abnormal situation identification rules define the judgment criteria and processing procedures for various abnormal situations. The risk tracing mechanism ensures that each risk handling decision has a complete record and responsibility traceability chain.
[0038] The second processing strategy targets key data and mainly includes hierarchical encryption mechanism, dynamic key management, access permission control and data desensitization rules. The hierarchical encryption mechanism uses encryption algorithms of different strengths according to the sensitivity of the data to ensure that the encryption strength matches the importance of the data. Dynamic key management defines the full life cycle management rules for key generation, distribution, update and destruction. Access permission control is based on the "principle of least privilege" and strictly limits the access scope of key data. Data desensitization rules define how to properly desensitize sensitive information in different usage scenarios, while protecting data security without affecting business processing.
[0039] When generating a processing strategy, the CL module extracts the contextual features of financial information and historical processing data, and dynamically optimizes the policy parameters through machine learning models. For example, it analyzes historical risk processing records and adjusts risk classification thresholds; analyzes data access patterns and optimizes encryption strength and key update cycles; monitors data flow efficiency and balances the relationship between security control and processing efficiency, thereby ensuring the adaptability and effectiveness of the processing strategy, which can be automatically adjusted as the business environment and risk conditions change.
[0040] After the CL module completes the financial information analysis and determines the risk data and key data, the iPaaS (Integration Platform as a Service) module, as the data integration and circulation hub of the financial and tax integration platform, first receives the risk data and key data from the CL module through a standardized API interface. The receiving process uses a secure transmission protocol (such as HTTPS) to ensure the security of the data transmission process. The data reception uses an asynchronous message queue mechanism to avoid data loss or processing delays caused by large data volumes or network fluctuations. The received data contains complete metadata tags, including data source, generation time, risk level, sensitivity level, processing strategy identifier, etc.
[0041] After receiving the data, the iPaaS module first verifies the data integrity, using technical means such as checksums and digital signatures to ensure that the received data has not been tampered with. At the same time, data format verification is performed to ensure that the data structure complies with predefined data exchange standards, such as the format specifications defined by JSON Schema or XML DTD. For data that fails verification, the iPaaS module will generate an exception report and trigger a retransmission mechanism to ensure data integrity and accuracy. Verified data will be temporarily stored in the iPaaS module's secure data buffer, which uses memory encryption technology to ensure that the data is also encrypted in memory to prevent memory theft attacks.
[0042] Before data flow, the iPaaS module will pre-process the data, including data format conversion, data compression and preliminary desensitization. Data format conversion is used to ensure that the data meets the input requirements of the data security monitoring module, such as converting JSON format to XML format. Data compression uses a lossless compression algorithm to reduce the amount of data transmission and improve transmission efficiency. Preliminary desensitization temporarily replaces or masks some sensitive information according to the security level of the data flow path to reduce the risk of data exposure during the flow process.
[0043] In this embodiment, the iPaaS module uses an intelligent routing mechanism to determine the data flow path. Intelligent routing makes decisions based on a variety of factors: data type (risk data or key data), data priority, load status of the data security monitoring module, network status, etc. The routing algorithm dynamically evaluates multiple possible transmission paths and selects the optimal path for data transmission. For high-priority data, the system will reserve a dedicated channel to ensure transmission speed; for large batches of data, a fragmented transmission strategy is adopted to divide the data into multiple small blocks for parallel transmission to improve transmission efficiency.
[0044] During the data flow, the iPaaS module implements full monitoring and logging through its built-in monitoring system and log system. Specifically, the monitoring system tracks the transmission status of each data packet in real time, including indicators such as sending time, receiving confirmation, and transmission rate. The log system records the complete data flow trajectory, including data identifiers, transmission timestamps, transmission paths, processing nodes, and other information.
[0045] The communication between the iPaaS module and the data security monitoring module uses the two-way authenticated TLS protocol to ensure the authenticity of the identities of both parties in the communication. Data transmission uses end-to-end encryption. Even if the data is intercepted during transmission, the original data cannot be obtained without the correct decryption key. In addition, the communication protocol also includes an anti-replay attack mechanism. Each data packet contains a unique timestamp and random number to prevent attackers from cheating by replaying historical data packets. The communication channel also supports an automatic recovery mechanism, which can automatically reconnect and continue unfinished data transmission tasks after a network interruption, ensuring the continuity and reliability of data flow.
[0046] Through the efficient data flow of the iPaaS module, risk data and key data can be safely and quickly transferred from the CL module to the data security monitoring module, laying the foundation for subsequent risk investigation and data encryption processing. The introduction of the iPaaS module significantly improves the data integration efficiency between the various components of the financial and tax integration platform, reduces the complexity of system integration, and provides flexibility and compatibility for future platform expansion and upgrades through standardized data exchange interfaces.
[0047] After receiving the risk data and key data transmitted by the iPaaS module, the data security monitoring module executes the first processing strategy and the second processing strategy generated by the CL module to ensure the security and compliance of the data during the flow process. The data security monitoring module first performs diversion processing on the received data, importing the risk data and key data into different processing pipelines respectively, and realizes parallel processing to improve efficiency. The diversion process accurately identifies the data type and applies the corresponding processing strategy based on the metadata tags in the data packet.
[0048] For risky data, the data security monitoring module strictly follows the first processing strategy to conduct risk screening. Specifically, basic security checks are first performed, including malicious code scanning, sensitive information leakage detection, and format verification. Malicious code scanning uses the latest virus signature library and heuristic analysis algorithm to detect whether the data contains potential malicious code or scripts. Sensitive information leakage detection uses regular expression matching and semantic analysis to identify unauthorized sensitive information that may exist in the data, such as personal identity information, bank account numbers, etc. Format verification ensures that the data complies with predefined security format specifications to prevent security vulnerabilities caused by format anomalies.
[0049] After the basic check, in-depth risk analysis begins. Specifically, a combination of rule-based and machine learning methods is used to conduct a comprehensive assessment of risk data. Rule-based analysis can apply preset risk identification rules, such as abnormal transaction amounts, abnormal transaction frequencies, abnormal counterparties, etc., to identify obvious risk patterns. Machine learning analysis uses trained anomaly detection models to identify hidden risk patterns. The anomaly detection model is trained based on historical transaction data and can identify abnormal behaviors that deviate from normal business patterns. In-depth risk analysis also combines external threat intelligence, such as known fraud pattern databases, abnormal lists of high-risk counterparties, etc., to further improve the accuracy of risk identification.
[0050] The risk screening results are divided into three levels: high, medium, and low, and a detailed risk report is generated. High-risk data will trigger a real-time alarm, and the relevant responsible persons will be notified through preset notification channels (such as internal system messages, emails, text messages, etc.). Medium-risk data will be marked and recorded in the risk log, waiting for manual review. Low-risk data will be allowed to continue to circulate, but a risk mark will be attached for reference in subsequent links. The risk report contains detailed information such as risk type, risk level, risk description, trigger rules, and recommended processing methods, providing a basis for subsequent decision-making.
[0051] At the same time, for critical data, the data security monitoring module strictly implements the second processing strategy for encryption protection. The encryption process first selects the appropriate encryption algorithm and key strength according to the data sensitivity level. High-sensitivity data uses high-strength encryption algorithms (such as AES-256, RSA-2048, etc.), medium-sensitivity data uses standard-strength encryption algorithms (such as AES-128, etc.), and low-sensitivity data may only undergo lightweight encryption or hash processing. Encryption key management adopts a distributed key management system that supports the full life cycle management of key generation, distribution, rotation, and revocation. Key storage is protected by a hardware security module (HSM) to ensure the security of the key itself. Specifically, the dynamic key management mechanism is such as Figure 7 As shown in the figure, it shows the full life cycle management process of key generation, distribution, update and destruction. First, the key generation is the responsibility of the key management system, which uses a high-strength encryption algorithm to ensure the randomness and security of the key; then, the key distribution is completed by the key distribution module through a secure channel (such as TLS) to ensure the security of the key transmission process; then, the key update is performed regularly by the key management module according to the security policy to deal with potential security threats. During the use of the key, if the key expires, the key destruction module uses secure erasure technology to completely destroy the key to ensure that it cannot be recovered; if it is not expired, the key will continue to be used.
[0052] The encryption process supports two modes: field-level encryption and file-level encryption. Field-level encryption selectively encrypts sensitive fields in structured data (such as ID numbers, bank account numbers, etc.), protecting sensitive information while preserving the data structure. File-level encryption encrypts the entire document or data packet, which is suitable for highly sensitive complete documents. Encryption also supports format-preserving encryption technology, which retains the format characteristics of the original data (such as length, character type, etc.) while encrypting the data, making it easier to process and verify the data without decrypting it.
[0053] After encryption is completed, encryption metadata is generated to record information such as the encryption algorithm, key identifier, encryption timestamp, etc., and these metadata are encapsulated together with the encrypted data. The encapsulation process uses digital signature technology to ensure the integrity and non-repudiation of encrypted data. Digital signatures are generated using an asymmetric encryption algorithm, which can verify whether the data has been tampered with during transmission and storage, and can also confirm the authenticity of the source of the data.
[0054] The data security monitoring module also implements full audit records, recording detailed information on all risk investigations and encryption operations, including operation time, operation type, operation results, operator (or system component), etc. Audit logs use tamper-proof storage mechanisms, such as blockchain technology or write-once-read-many (WORM) storage, to ensure the authenticity and integrity of audit records.
[0055] After completing risk screening and data encryption, the data security monitoring module will accurately transfer the processed risk data and encrypted key data to the corresponding business processing platform. Before data transfer, the data security monitoring module first identifies the target platform and makes routing decisions. Target platform identification is based on the business attributes, processing requirements and security level of the data, and accurately locates the target platform to which the data should flow from the n business processing platforms integrated in the tax integration platform. Routing decisions take into account factors such as network conditions, platform load, and data priority, and select the optimal transmission path and transmission time for each batch of data.
[0056] The data flow adopts an intelligent scheduling mechanism to dynamically adjust the data transmission rate and batch size according to the processing capacity and current load of the business processing platform. For platforms with strong processing capacity and low load, the data batch size is increased and the transmission frequency is increased; for platforms with limited processing capacity or high current load, the data batch size is reduced and the transmission frequency is reduced to avoid performance bottlenecks on the target platform due to sudden data increases. At the same time, it ensures that high-priority data (such as tax data involving statutory reporting deadlines) can be transmitted and processed first, ensuring timely processing of key business even when the system load is high.
[0057] The data transmission process uses secure channel technology to ensure the security of data during network transmission. The secure channel is established based on the TLS / SSL protocol and supports two-way authentication to ensure the authenticity of the identities of both parties in the communication.
[0058] After the data arrives at the target business processing platform, the data security monitoring module will execute the data delivery confirmation process. Delivery confirmation uses a reliable message transmission mechanism, requiring the target platform to return a confirmation message after successfully receiving and verifying the data. The confirmation message contains information such as data identification, receiving timestamp, and data integrity check results. If the confirmation message is not received within the scheduled time, or the confirmation message indicates that the data reception is abnormal, the retransmission mechanism is automatically started to ensure reliable data delivery.
[0059] For encrypted critical data, the data security monitoring module also needs to coordinate key distribution to ensure that the target platform can correctly decrypt and process data. Key distribution uses a secure key exchange protocol, such as a key distribution mechanism based on PKI. Key distribution and data transmission are carried out in different secure channels to avoid security risks caused by single point failure. Key usage permissions are strictly controlled, and only authorized business processing platforms can obtain the corresponding decryption keys.
[0060] The entire data flow process is monitored and audited. The monitoring system tracks the data flow status in real time, including transmission progress, target platform response, abnormal events, etc. The monitoring data is presented through a visual dashboard, which allows managers to understand the data flow in real time. The audit system records the complete data flow trajectory, including data identification, flow time, source platform, target platform, transmission status and other information.
[0061] Through the precise data flow of the data security monitoring module, the integrated finance and taxation platform realizes the safe and efficient distribution of risk data and key data, ensuring that each business processing platform can obtain the required data in a timely manner and process it accordingly, significantly improving the processing efficiency and security of corporate finance and taxation data, and providing solid technical support for corporate finance and taxation management. At the same time, the complete monitoring and auditing mechanism also ensures the traceability and compliance of the data flow process, effectively preventing security risks such as data leakage and data abuse, and providing all-round protection for corporate finance and taxation data security.
[0062] In another embodiment, the RPA module includes a data processing rule library, and after the data security monitoring module transfers the risk data and the encrypted key data to the corresponding business processing platform, it also includes: S1. The data security monitoring module generates a feedback report and sends it to the CL module. The feedback report includes risk data processing effect, risk probability distribution, key data encryption effect, and key usage record; S2. The CL module optimizes the first processing strategy and the second processing strategy based on the feedback report, and updates the data processing rules of the RPA module; The CL module optimizes the first processing strategy and the second processing strategy based on the feedback report, and updates the data processing rules of the RPA module, including: S21. Adjust the risk data classification mechanism in the first processing strategy according to the risk data processing effect in the feedback report; S22. Based on the risk probability distribution in the feedback report, adjust the parameters of the risk assessment model in the first processing strategy; S23, adjusting the encryption algorithm selection strategy for the key data in the second processing strategy according to the encryption effect of the key data in the feedback report; S24. Based on the key usage record in the feedback report, update the dynamic key management mechanism in the second processing strategy.
[0063] After the risk data and encrypted key data are transferred to the corresponding business processing platform, the data security monitoring module generates a feedback report to evaluate the effect of data processing and provide a basis for strategy optimization. The content of the feedback report includes the risk data processing effect, risk probability distribution, key data encryption effect and key usage record. The risk data processing effect refers to the result of the risk data being identified, classified and processed during the circulation process, such as the processing success rate of high-risk data and the processing efficiency of medium-risk data. The risk probability distribution refers to the distribution of data of different risk levels during the processing process, such as the proportion of high-risk data and the proportion of low-risk data. The key data encryption effect refers to the security and integrity of the encrypted key data during the circulation process, such as the decryption success rate of encrypted data and the strength of the encryption algorithm. The key usage record refers to the use of the key during the encryption and decryption process, such as the generation time, usage frequency, and update cycle of the key. The process of generating a feedback report first collects and analyzes the circulation data and extracts relevant indicators. The statistical analysis tool can be used to calculate the risk data processing effect, the data visualization tool can be used to display the risk probability distribution, the encryption performance test tool can be used to evaluate the key data encryption effect, and the log analysis tool can be used to extract the key usage record.
[0064] After receiving the feedback report, the CL module optimizes the first processing strategy and the second processing strategy based on the report content, and updates the data processing rules of the RPA module. The first processing strategy is mainly for risk data, including risk data classification mechanism, risk assessment model, abnormal data identification rules and risk data traceability mechanism. The second processing strategy is mainly for key data, including hierarchical encryption strategy, dynamic key management mechanism, access control strategy and data desensitization processing rules. The process of optimizing the strategy first determines the parameters and conditions that need to be adjusted by analyzing the feedback report. For example, according to the risk data processing effect, adjust the threshold parameters of the risk data classification mechanism; according to the risk probability distribution, adjust the evaluation factor of the risk assessment model; according to the key data encryption effect, adjust the encryption algorithm selection strategy; according to the key usage record, update the key update cycle of the dynamic key management mechanism. The process of updating the data processing rules of the RPA module ensures that the RPA module can apply the latest strategy when processing data by writing the optimized strategy parameters and conditions into the rule base. By optimizing strategies and updating rules, the efficiency and security of data processing can be improved, and the stability and reliability of data flow can be ensured.
[0065] In the process of optimizing the first processing strategy, the risk data classification mechanism divides the data into high risk, medium risk and low risk according to the risk level of the data. The process of adjusting the classification mechanism first determines the threshold parameters that need to be adjusted by analyzing the risk data processing effect in the feedback report. If the processing success rate of high-risk data is low, it is necessary to lower the threshold of high-risk data and mark more data as high risk; if the processing efficiency of low-risk data is high, it is necessary to increase the threshold of low-risk data and mark more data as low risk. The process of adjusting the threshold parameters can be achieved through statistical analysis, such as using regression analysis to determine the optimal threshold. By adjusting the risk data classification mechanism, the accuracy and efficiency of risk data processing can be improved, ensuring that high-risk data is processed in a timely manner and low-risk data is processed efficiently.
[0066] In the process of optimizing the first processing strategy, the risk assessment model predicts the risk probability of the data based on its characteristics. The process of adjusting the model parameters first determines the assessment factors that need to be adjusted by analyzing the risk probability distribution in the feedback report. For example, if the proportion of high-risk data is high, the weights of features such as amount and transaction frequency need to be increased; if the proportion of low-risk data is high, the weights of these features need to be reduced. The process of adjusting the assessment factors is achieved through machine learning methods, such as using the gradient descent method to optimize model parameters. By adjusting the parameters of the risk assessment model, the accuracy of risk prediction can be improved and risk data can be properly processed.
[0067] In the process of optimizing the second processing strategy, the encryption algorithm selection strategy selects different encryption algorithms according to the sensitivity of the key data. The process of adjusting the selection strategy first determines the encryption strength that needs to be adjusted by analyzing the encryption effect of the key data in the feedback report. If the decryption success rate of the encrypted data is low, it is necessary to reduce the encryption strength and select a more efficient encryption algorithm to reduce the complexity or failure rate in the decryption process; if the security of the encrypted data is insufficient (for example, the decryption success rate is too high or there are security vulnerabilities), it may be necessary to increase the encryption strength and select a more secure encryption algorithm to enhance the data protection capability.
[0068] In the process of optimizing the second processing strategy, the dynamic key management mechanism regularly updates and disperses the stored keys according to the usage of the keys. The process of updating the management mechanism first determines the key update cycle that needs to be adjusted by analyzing the key usage records in the feedback report. For example, if the key is used frequently, the update cycle may need to be shortened to improve the security of the key; if the key is used less frequently, the update cycle may need to be extended to improve the management efficiency of the key. By updating the dynamic key management mechanism, the security and management efficiency of the keys can be improved to ensure that the encrypted data is effectively protected.
[0069] This embodiment, by responding to multi-source data entry instructions, converts heterogeneous data from multiple channels such as ERP system, CRM system, electronic invoice platform, bank statement and supplier system, including structured data, semi-structured data and unstructured data, into structured data, and identifies financial information therein, thereby solving the problem of difficulty in integrating multi-source heterogeneous data in traditional financial processing; the CL module analyzes the financial information according to the determined processing order, identifies risk data and key data, and dynamically generates targeted first processing strategy and second processing strategy according to data characteristics, thereby enhancing the intelligent processing capability of complex financial data; the iPaaS module receives risk data and key data as an integration platform, and securely transfers them to the data security monitoring module, effectively solving the limitation that data flow between traditional systems relies on manual intervention or simple interface calls, and eliminating the problem of information islands; the data security monitoring module uses the first processing strategy to conduct risk screening on risk data and the second processing strategy to encrypt key data, respectively, providing security protection for sensitive information in financial data; the data security monitoring module transfers the risk data and encrypted key data that have undergone risk screening to the corresponding business processing platform, thereby realizing secure data flow across systems. Through the collaborative process, not only the limitations of single RPA technology in processing complex financial data are overcome, but also an end-to-end data security flow mechanism is built through the introduction of iPaaS modules and data security monitoring modules, enabling enterprises to achieve seamless data exchange and collaborative work between multiple business processing systems under the premise of ensuring data security, significantly improving financial processing efficiency, reducing the risk of human errors, and enhancing data security. Compared with traditional solutions that rely on manual operations or single RPA technology, this technical solution realizes the automation and intelligence of the entire process of financial data from entry, analysis, flow to secure processing through the collaborative work of multiple modules.
[0070] In one implementation of this embodiment, the CL module generates the first processing strategy and the second processing strategy, including the following steps: S210, the CL module extracts context features of financial information and obtains historical data; S220, the CL module dynamically generates a first processing strategy and a second processing strategy based on the context features and the historical data; The first processing strategy includes a risk data classification mechanism, a risk assessment model, an abnormal data identification rule and a risk data tracing mechanism. The risk data classification mechanism is used to determine the risk level of risk data. The risk assessment model is used to determine the risk probability of risk data according to the risk level of risk data. The abnormal data identification rule is used to determine the abnormal data in risk data according to the risk probability. The risk data tracing mechanism is used to record the processing flow of risk data. The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy and data desensitization processing rules. The hierarchical encryption strategy is used to determine the sensitivity of key data and determine the corresponding encryption algorithm based on the sensitivity. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a dispersed manner. The access permission control strategy is used to set data access permissions. The data desensitization processing rules are used to mask or replace sensitive fields in key data.
[0071] In the data flow process of the integrated finance and taxation platform, the CL module first needs to extract the contextual features of financial information and obtain relevant historical data, which is the basis for generating effective processing strategies. Contextual feature extraction adopts a multi-dimensional analysis method to extract features from multiple dimensions such as the content, source, time, and association of financial information. Feature extraction in the content dimension focuses on the attribute characteristics of the financial data itself, including but not limited to core financial elements such as transaction amount, transaction type, transaction frequency, counterparty, and accounting subjects. Natural language processing technology is used to perform semantic analysis on unstructured financial descriptions, extract keywords, entities, and semantic relationships, and convert them into quantifiable feature vectors. For structured data, numerical features, category features, and time series features are directly extracted to construct a multi-dimensional feature space.
[0072] Feature extraction from the source dimension focuses on the generation channels and transmission paths of financial information, including data source systems, input methods, transmission protocols, etc. A credibility scoring mechanism can be established for data from different sources, and different credibility weights can be assigned to each data source based on factors such as historical data quality, system security level, and data consistency. For example, data from the core financial system of an enterprise that has undergone multiple audits usually has a higher credibility score than data imported from outside or entered manually.
[0073] The feature extraction of the time dimension focuses on the time attributes of financial information, including the time when the data is generated, the accounting period, the reporting period, etc. It can analyze the time series characteristics of the data and identify seasonal patterns, cyclical changes, and abnormal time points. Through time dimension analysis, abnormal transactions that do not conform to the normal business cycle can be found, such as large capital flows during non-working hours and abnormal accounting adjustments near the reporting date.
[0074] Feature extraction in the dimension of association relationships focuses on the intrinsic connections between financial information and builds a data association network. Graph analysis technology can be used to construct a financial relationship map by taking financial entities (such as accounts, transactions, customers, suppliers, etc.) as nodes and their relationships (such as capital flow, ownership, business transactions, etc.) as edges. Through graph analysis, hidden association relationships can be discovered, such as potential risk points such as circular transactions and related-party transactions. Association analysis also includes cross-system data consistency checks to verify whether the records of the same financial matters in different business systems are consistent.
[0075] After the context feature extraction is completed, the CL module further obtains historical data related to the current financial information. The historical data acquisition adopts an intelligent retrieval mechanism to retrieve similar cases from the historical database based on the feature vector of the current financial information. The retrieval uses vector similarity calculation methods, such as cosine similarity, Euclidean distance, etc., to find the closest historical records in the feature space.
[0076] After completing the context feature extraction of financial information and the acquisition of historical data, the CL module dynamically generates the first processing strategy and the second processing strategy. The generation of the first processing strategy focuses on the management and control of risk data, including risk data classification mechanism, risk assessment model, abnormal data identification rules and risk data traceability mechanism. The risk data classification mechanism is based on the risk index and divides risk data into multiple levels, such as extremely high risk, high risk, medium risk and low risk. The classification standard takes into account industry characteristics and corporate risk preferences, and can be adjusted through configuration parameters.
[0077] The risk assessment model uses a multi-model fusion method, combined with a rule engine and a machine learning algorithm, to calculate the risk probability of risk data. The rule engine contains deterministic rules encoded with expert knowledge, such as "the amount of a single transaction exceeds the authorized limit" and "large capital outflows at unusual times" and other clear risk signals. Machine learning algorithms include anomaly detection models (such as isolation forests, autoencoders) and classification models (such as gradient boosting trees, neural networks), which can capture complex risk patterns. Model fusion uses weighted voting or stacking integration methods to integrate the prediction results of multiple models to improve the accuracy and stability of risk assessment. Among them, the flowchart of the risk assessment model can be referred to Figure 6 ,First, the risk factors extracted from the financial information are used as the ,input of risk assessment, and a weight is assigned to each risk factor, which reflects the ,degree of impact of the factor on the overall risk. ,Based on the risk factors and their weights, a comprehensive risk score is calculated. ,Based on the risk score, the risk is divided into three levels, high, medium and low.
[0078] Abnormal data identification rules are based on risk probability thresholds and business rules to identify abnormal data that require special attention. Identification rules not only consider the risk probability of a single piece of data, but also consider the correlation and timing patterns between data, and can discover collaborative anomalies scattered across multiple records. For example, it can identify scattered transactions with abnormal frequencies, although the single amount is not large, or discover fund circulation across multiple accounts.
[0079] The risk data traceability mechanism is designed to record the complete processing history of risk data to ensure the auditability and compliance of the risk processing process. The traceability mechanism can use blockchain or tamper-proof log technology to record every link of data processing, including risk identification time, assessment results, processing decisions, execution operations and responsible persons. The traceability records use timestamp and digital signature technology to ensure authenticity, and support multi-dimensional query and visual display, which is convenient for post-audit and risk review.
[0080] The second processing strategy includes hierarchical encryption strategy, dynamic key management mechanism, access control strategy and data desensitization processing rules. The hierarchical encryption strategy selects appropriate encryption algorithms and parameters for data of different sensitivity levels based on the sensitivity index. Highly sensitive data may use stronger encryption algorithms and more complex encryption modes, while medium and low sensitive data may use lightweight encryption or hash protection.
[0081] The dynamic key management mechanism is responsible for the generation, distribution, update and destruction of keys throughout their life cycle. Key updates are triggered by both time and events, with keys rotated regularly and updated immediately when potential security threats are detected. Distributed key storage uses secret sharing technology to split the master key into multiple shares, which are stored in different security domains. Only when a sufficient number of shares are collected can the original key be reconstructed, effectively preventing the risk of single-point leakage.
[0082] The access control policy adopts a hybrid access control model based on roles and attributes to manage data access rights in a refined manner. Permission control not only considers user roles, but also contextual factors such as data attributes, access time, and access location to achieve dynamic, context-aware access control. For example, the same user may be granted different levels of data access rights at different times or in different network environments. The permission policy supports the principle of least privilege and separation of duties, ensuring that users can only access the minimum data set required to perform their duties, and preventing abuse of power through separation of duties.
[0083] Data desensitization rules provide field-level protection measures for data that needs to be circulated over a wide range but contains sensitive fields. Desensitization rules select appropriate desensitization techniques based on field type and sensitivity, such as masking (such as displaying a credit card number as "**** **** **** 1234"), data replacement (replacing real data with fictitious but consistent data in the same format), and range (replacing exact values with range values). Desensitization preserves the business value and statistical characteristics of data while effectively protecting personal privacy and business secrets.
[0084] In actual implementation, dynamic policy generation relies on machine learning models and rule engines. For example, a random forest model or a neural network model is used to predict the risk level and sensitivity of data based on contextual features and historical data. The rule engine generates specific processing strategies based on preset business rules.
[0085] The first processing strategy and the second processing strategy dynamically generated in this implementation are respectively for risk data and key data, realizing risk classification, encryption protection and permission control of data. By combining machine learning models and rule engines, dynamic strategy generation can adapt to complex and changeable financial data environments and improve the efficiency and security of data processing. Ultimately, this technical solution not only solves the problem of difficulty in integrating multi-source heterogeneous data in traditional financial processing, but also significantly improves the automation level and security of financial data processing through an intelligent strategy generation mechanism, realizing the intelligent processing of the entire process of financial data from context feature extraction to dynamic strategy generation.
[0086] In one implementation of this embodiment, the CL module dynamically generates a first processing strategy and a second processing strategy based on context features and historical data, including the following steps: S310, the CL module inputs the data features and the context features as input parameters into the pre-built machine learning model to analyze and obtain the historical processing records of the risk data and the historical encryption records of the key data; S320, the CL module determines the parameters and conditions of the first processing strategy according to the historical processing records, and applies the parameters and conditions of the first processing strategy to the first processing strategy, wherein the parameters and conditions of the first processing strategy include the threshold parameters of the risk data classification mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rules, and the record items of the risk data tracing mechanism; S330, the CL module determines the parameters and conditions of the second processing strategy based on the historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy, wherein the parameters and conditions of the second processing strategy include the encryption strength of the hierarchical encryption strategy, the key update cycle of the dynamic key management mechanism, the permission matrix of the access permission control strategy, and the desensitization method of the data desensitization processing rules.
[0087] Data features refer to the attributes of the financial data itself, such as amount, transaction type, timestamp, etc. Contextual features include environmental information such as the source of the data, operator, business scenario, etc. These features are used together as input parameters for machine learning models. Pre-built machine learning models usually use supervised learning or unsupervised learning methods, such as random forests, support vector machines, or neural networks. Machine learning models learn the relationship between data features and processing results by training historical data. For example, the model can learn that certain types of transactions (such as large transfers) are more likely to be marked as high risk, or that transactions processed by certain operators (such as new employees) are more likely to be abnormal. By inputting the data features and contextual features of the current data, the machine learning model can predict its risk level and sensitivity, and refer to historical processing records and encryption records to generate corresponding processing strategies.
[0088] In actual implementation, the extraction of data features and context features can be achieved through data preprocessing technology. For example, for structured data, field values are directly extracted as data features; for unstructured data, natural language processing (NLP) technology is used to extract key information. Context features are generated by analyzing metadata and business rules. By inputting data features and context features into the model, historical processing records of risk data and historical encryption records of key data can be analyzed.
[0089] After obtaining the historical processing records of risk data, the parameters and conditions of the first processing strategy are determined, specifically, Figure 4 As shown, the first processing strategy includes a risk data grading mechanism, a risk assessment model, an abnormal data identification rule and a risk data tracing mechanism. The threshold parameters of the risk data grading mechanism are determined according to the risk level distribution in the historical processing records. For example, if the historical data shows that the risk level of a certain type of transaction is mainly concentrated in "medium risk" and "high risk", the threshold parameter can be set to a critical value to distinguish these two types of risk levels. The evaluation factor of the risk assessment model is determined according to the risk probability distribution in the historical data. For example, when using a logistic regression model, the evaluation factor can be the weight of features such as transaction amount and transaction frequency. The judgment condition of the abnormal data identification rule is determined according to the abnormal data characteristics in the historical processing records. For example, if the historical data shows that the risk probability of a certain type of transaction exceeds 0.8, it is usually abnormal data, then the judgment condition is set to the risk probability greater than 0.8. The record items of the risk data tracing mechanism are determined according to the audit requirements in the historical processing records. For example, the record items can include data source, processing personnel, processing time, etc.
[0090] In actual implementation, the determination of parameters and conditions is usually achieved through statistical analysis or machine learning methods. For example, cluster analysis is used to determine the threshold parameters of the risk data classification mechanism, and regression analysis is used to determine the evaluation factors of the risk assessment model. By applying the determined parameters and conditions to the first processing strategy, the strategy can be made dynamic and personalized, and the accuracy and efficiency of risk data processing can be improved.
[0091] After obtaining the historical encryption records of key data, the parameters and conditions of the second processing strategy are determined. Specifically, the second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy, and a data desensitization processing rule. The encryption strength of the hierarchical encryption strategy is determined according to the distribution of sensitivity in the historical encryption records. For example, if historical data shows that the sensitivity of a certain type of data is mainly concentrated in "high sensitivity" and "medium sensitivity", the encryption strength can be set to AES-256 and AES-128. The key update cycle of the dynamic key management mechanism is determined according to the frequency of key use in the historical encryption records. For example, if historical data shows that the frequency of use of a certain type of key is high, the update cycle can be set to a shorter time interval. The permission matrix of the access permission control strategy is determined according to the user roles and permission distribution in the historical encryption records. For example, the permission matrix can include the access scope of roles such as financial managers and ordinary employees. The desensitization method of the data desensitization processing rule is determined according to the desensitization requirements in the historical encryption records. For example, the desensitization method can include masking, replacement, etc.
[0092] In specific implementation, cluster analysis can be used to determine the encryption strength of the hierarchical encryption strategy, and regression analysis can be used to determine the key update cycle of the dynamic key management mechanism. By applying the determined parameters and conditions to the second processing strategy, the strategy can be dynamic and personalized, and the accuracy and efficiency of key data processing can be improved.
[0093] In this implementation, the input of data features and context features provides comprehensive input information for machine learning model analysis, ensuring the pertinence and effectiveness of the strategy. The parameters and conditions determined based on historical processing records and encrypted records enable the first processing strategy and the second processing strategy to be dynamic and personalized. By combining statistical analysis or machine learning methods, the determination of parameters and conditions can adapt to the complex and changeable financial data environment and improve the efficiency and security of data processing. Ultimately, this technical solution not only solves the problem of difficulty in integrating multi-source heterogeneous data in traditional financial processing, but also significantly improves the automation level and security of financial data processing through an intelligent strategy parameter determination mechanism.
[0094] In one implementation of this embodiment, the RPA module classifies and sorts the financial information, and determines the processing order of the classified and sorted financial information, including the following steps: S410. The RPA module divides the financial information based on preset data categories to obtain at least one financial data set. S420, the RPA module determines the correlation between each financial data set and other financial data sets, and merges the financial data sets with a higher correlation than a preset correlation to obtain at least one correlated financial data set; S430. For any associated financial data set, the RPA module uses preset scoring rules to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set, where the total score is the sum of the time sensitivity score and the data value score, and the order of the total scores from high to low is used as the processing order of the associated financial data sets.
[0095] Figure 3 A schematic diagram of RPA module data processing provided in an embodiment of the present application is shown. Figure 3 As shown in the figure, in the process of financial information processing, the RPA module divides the financial information by preset data categories and classifies the multi-source financial data into several financial data sets. The preset data categories usually include invoice data, contract data, account data and report data, etc. These categories are defined according to the actual needs and business processes of enterprise financial management. For example, invoice data includes electronic invoices, scanned copies of paper invoices, etc., contract data includes supplier contracts, customer contracts, etc., account data includes bank statements, accounts receivable, etc., and report data includes financial statements, tax reports, etc. The classification process first determines the category to which the financial data belongs by analyzing the metadata and content characteristics of the financial data. For example, for electronic invoices, by identifying key fields such as invoice number, amount, date, etc., it is classified as invoice data; for bank statements, by identifying key fields such as account information and transaction records, it is classified as account data. In actual implementation, data classification can be achieved through a rule engine. The rule engine matches data features through preset rules. For example, if the data contains the "invoice number" field, it is classified as invoice data.
[0096] Based on the classification of financial information, determining the correlation between data sets is a key step to achieve data integration and efficient processing. Correlation refers to the correlation between different data sets in terms of business logic or data processing flow. For example, invoice data and account data usually have a high correlation because invoice information needs to be checked with account records; contract data and report data may also have a high correlation because contract information needs to be reflected in financial statements. The process of determining the correlation first calculates the similarity or correlation by analyzing the content characteristics and business rules of the data sets. For example, the similarity between data sets is calculated using cosine similarity or Jaccard similarity. For invoice data and account data, if the two contain the same transaction number or amount information, their correlation is high. In actual implementation, the calculation of correlation can be achieved through statistical analysis or machine learning methods. For example, cluster analysis is used to classify data sets with similar characteristics into the same group, or association rule mining technology (such as the Apriori algorithm) is used to discover the correlation between data sets. By merging data sets with a correlation higher than the preset correlation, several related financial data sets can be obtained. For example, invoice data and account data are combined into one associated data set, and contract data and report data are combined into another associated data set. By building associated data sets, data integration and collaborative processing can be achieved, improving the efficiency and accuracy of data processing.
[0097] After the associated financial data sets are obtained, the processing order is determined based on the time sensitivity score and the data value score. The time sensitivity score refers to the urgency of the data set in terms of processing time. For example, some data needs to be processed within a specific time, otherwise it will affect the business process. The data value score refers to the importance of the data set in business decision-making or financial analysis. For example, some data has a significant impact on the accuracy of financial statements or the compliance of tax declarations. Scoring rules are usually defined based on business needs and historical data. For example, the time sensitivity score can be determined based on the deadline or processing cycle of the data, and the data value score can be determined based on the amount, business type or scope of impact of the data. For each associated data set, its time sensitivity score and data value score are first calculated, and then the two are added to obtain the total score. For example, for the associated data sets of invoice data and account data, if their deadlines are close and the amount is large, their time sensitivity score and data value score are both high, and the total score is also high. In actual implementation, the scoring rule can be implemented by weighted summation. The processing order of the associated data sets is determined by sorting the total scores from high to low. For example, the data set with the highest total score is processed first, and the data set with the lowest total score is processed last. Through scoring and sorting, priority management of data processing can be achieved, ensuring that key data is processed in a timely manner, and improving the efficiency and accuracy of financial management.
[0098] This implementation method divides financial information based on preset data categories, ensuring structured management and orderly processing of data. By determining the correlation between data sets and merging highly correlated data sets, data integration and collaborative processing are achieved. Time sensitivity scores and data value scores are determined through scoring rules, and the total score is calculated to achieve priority management of the data processing order. Ultimately, this technical solution not only solves the problem of difficult data classification and priority management in traditional financial processing, but also significantly improves the efficiency and accuracy of financial data processing through an intelligent scoring and sorting mechanism.
[0099] In one implementation of this embodiment, the CL module includes a basic data layer, a business logic layer, and a risk control layer. The CL module determines the risk data and key data of financial information, including the following steps: S510. For each associated financial data set, at the basic data layer, the CL module performs format verification on the associated financial data set, and treats the data in the associated financial data set that fails the format verification as risk data; S520. At the business logic layer, the CL module performs business logic consistency verification on the associated financial data set, and regards the data in the associated financial data set that fails the business logic consistency verification as risk data. S530. At the risk control layer, the CL module performs data sensitivity verification on the associated financial data set, and uses the data in the associated financial data set that has not passed the data sensitivity verification as key data. (Involving the company's core financial indicators, key tax declaration information, and sensitive business data) In the process of financial data processing, format validation is the first step to ensure data integrity and accuracy. The basic data layer is responsible for format validation of the associated financial data set to identify data that does not meet the preset format requirements. Format validation includes multiple aspects such as data type, field length, value range, date format, etc. For example, for invoice data, the validation fields include invoice number (must be a number and fixed length), amount (must be a number and greater than zero), date (must conform to the YYYY-MM-DD format), etc. For accounting data, the validation fields include account number (must be a combination of letters and numbers and fixed length), transaction amount (must be a number and not empty), transaction date (must conform to a specific format), etc. The format validation process first parses the data field, extracts its type and value, and then compares it with the preset format rules. For example, regular expressions are used to validate the date format, and value range checks are used to validate the amount range. For data that fails format validation, it is marked as risky data, and its error type and location are recorded. For example, if the amount field of a transaction is empty or negative, it is marked as risky data. In actual implementation, format validation can be implemented through a rule engine. For example, use a rules engine such as Drools to define validation rules.
[0100] On the basis of format verification, the business logic layer is responsible for business logic consistency verification of the associated financial data set to identify data that does not comply with business rules. Business logic consistency verification includes multiple aspects such as data relevance, business rule compliance, and logical consistency. For example, for invoice data, verify its consistency with account data to ensure that the invoice amount is consistent with the amount in the account record; for contract data, verify its consistency with report data to ensure that the contract amount is consistent with the amount in the financial report. The process of business logic consistency verification first determines its consistency rules by analyzing the association between data fields. For example, use SQL query to verify the consistency of invoice data with account data, or use the business rule engine to verify the consistency of contract data with report data. For data that fails the business logic consistency verification, it is marked as risky data, and its error type and location are recorded. For example, if the amount of an invoice is inconsistent with the amount in the account record, it is marked as risky data. In actual implementation, business logic consistency verification can be implemented through database triggers. For example, use database triggers to automatically verify data consistency.
[0101] On the basis of business logic consistency verification, the risk control layer is responsible for data sensitivity verification of related financial data sets to identify data containing sensitive information. Data sensitivity verification includes multiple aspects such as sensitive field identification, sensitive data detection, and compliance checking. For example, for invoice data, sensitive fields include bank account numbers, tax numbers, etc.; for account data, sensitive fields include customer information, transaction amounts, etc. The process of data sensitivity verification first analyzes the data fields to identify their sensitivity. For example, regular expressions are used to identify sensitive fields such as bank account numbers and tax numbers. For data that fails data sensitivity verification, it is marked as critical data and its sensitive type and location are recorded. For example, if a transaction contains bank account information, it is marked as critical data. In actual implementation, Drools can be used to define sensitive field identification rules, and data security and compliance can be ensured through data sensitivity verification.
[0102] In this implementation, the format verification of the basic data layer ensures the integrity and accuracy of the data, providing a reliable basis for subsequent business logic verification and risk control. The business logic consistency verification of the business logic layer ensures that the data complies with business processes and rules, providing a reliable basis for subsequent risk control. The data sensitivity verification of the risk control layer ensures the security and compliance of the data, providing a reliable basis for subsequent encryption processing and permission control, effectively solving the difficulties of data verification and risk control in traditional financial processing, and significantly improving the efficiency and security of financial data processing through intelligent verification mechanisms.
[0103] In one implementation of this embodiment, after the iPaaS module receives the risk data and the key data, the following steps are included: S610, the iPaaS module extracts the first feature of the risk data and the second feature of the key data, and determines the optimal data flow path based on the first feature and the second feature; S620 and iPaaS modules monitor the efficiency and quality of the optimal data flow path in real time; S630, iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path.
[0104] After receiving the risk data and key data, the iPaaS module first extracts the first feature of the risk data and the second feature of the key data to determine the optimal data flow path. The first feature refers to the attributes of the risk data, such as risk level, data volume, processing priority, etc.; the second feature refers to the attributes of the key data, such as sensitivity, encryption requirements, access rights, etc. The process of extracting features is achieved by analyzing the metadata and content information of the data. For example, for risk data, its risk level (such as high risk, medium risk, low risk) and data volume (such as file size, number of records) are extracted; for key data, its sensitivity (such as highly sensitive, ordinary sensitive) and encryption requirements (such as whether AES-256 encryption is required) are extracted. Based on the above features, the iPaaS module can determine the optimal data flow path. The selection of the optimal path is usually based on multiple factors, including network bandwidth, transmission delay, data security requirements, etc. For example, for risk data with high risk and large data volume, a high-bandwidth, low-latency path is selected; for highly sensitive key data, a path with high encryption strength and strong security is selected.
[0105] After determining the optimal data flow path, real-time monitoring of the efficiency and quality of the path is a key step to ensure the stability and reliability of data transmission. The efficiency of the path is characterized by network latency and bandwidth utilization, and the quality of the path is characterized by packet loss rate. The real-time monitoring process first deploys monitoring tools or sensors to collect network performance data of the path. For example, use the Ping command to measure network latency, use bandwidth monitoring tools to measure bandwidth utilization, and use packet analysis tools to measure packet loss rate. The collected data is analyzed in real time to generate a monitoring report. For example, if the network latency of a path exceeds a preset threshold, it is marked as an inefficient path; if the packet loss rate exceeds a preset threshold, it is marked as a low-quality path. In actual implementation, real-time monitoring can be achieved through a network monitoring system, such as Nagios.
[0106] Based on real-time monitoring, the data transmission compression rate and encryption strength can be dynamically adjusted to optimize the path performance. The data transmission compression rate refers to the ratio of data compression during transmission, and the encryption strength refers to the level of data encryption during transmission. The dynamic adjustment process first determines the adjustment strategy by analyzing the efficiency and quality of the path. For example, if the network delay of the path is high, the compression rate is reduced to reduce the processing time; if the bandwidth occupancy rate of the path is low, the compression rate is increased to reduce the amount of data. For encryption strength, if the security of the path is strong, the encryption strength is reduced to improve the transmission efficiency; if the security of the path is weak, the encryption strength is increased to enhance data security. In actual implementation, dynamic adjustment can be achieved through adaptive algorithms, such as adjustment algorithms based on feedback control. Through dynamic adjustment, the transmission efficiency of the path can be optimized while ensuring data security, and the best performance of data flow can be achieved.
[0107] This implementation method extracts features and determines the optimal path, ensuring that data is transmitted with both efficiency and security. The efficiency and quality of the path are monitored in real time to promptly identify and resolve performance issues. The data transmission compression rate and encryption strength are dynamically adjusted to optimize path performance and achieve the best balance in data flow. Ultimately, it not only solves the problem of balancing efficiency and security in traditional data flow, but also significantly improves the efficiency and security of data flow through intelligent monitoring and adjustment mechanisms, and realizes intelligent management of the entire process of risk data and key data from feature extraction to path optimization.
[0108] In one implementation of this embodiment, the efficiency of the optimal data flow path is characterized by network delay and bandwidth occupancy, and the quality of the optimal data flow path is characterized by data packet loss rate. The iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path, including the following steps: The S710 and iPaaS modules use a pre-built adaptive adjustment model to calculate the optimal combination of data transmission compression rate and encryption strength based on network latency, bandwidth occupancy, and packet loss rate to balance data security and transmission efficiency of the optimal data flow path.
[0109] In the process of data flow, network delay, bandwidth utilization and packet loss rate are key indicators to measure the efficiency and quality of the path. Network delay refers to the time required for data to travel from the sender to the receiver, usually in milliseconds (ms); bandwidth utilization refers to the proportion of current network bandwidth used, usually expressed as a percentage (%); packet loss rate refers to the proportion of data packets lost during transmission to the total number of data packets, usually expressed as a percentage (%). These indicators together determine the performance of the data flow path. In order to achieve the best balance between data security and transmission efficiency, the iPaaS module dynamically calculates the combination of the best data transmission compression rate and the best encryption strength through a pre-built adaptive adjustment model. The adaptive adjustment model is an intelligent algorithm based on machine learning that can automatically adjust parameters according to real-time monitoring data to optimize system performance. The input parameters of the model include network delay, bandwidth utilization and packet loss rate, and the output parameters are the best data transmission compression rate and the best encryption strength.
[0110] The process of building an adaptive adjustment model first requires the collection of a large amount of historical data, including latency, bandwidth occupancy, packet loss rate, and corresponding data transmission compression rate and encryption strength under different network conditions. These data are used to train the model so that it can learn the relationship between input parameters and output parameters. For example, when the network latency is high, the model tends to reduce the compression rate to reduce processing time; when the bandwidth occupancy rate is low, the model tends to increase the compression rate to reduce the amount of data; when the packet loss rate is high, the model tends to increase the encryption strength to enhance data security. The model is usually trained using supervised learning methods, such as regression analysis or neural networks. Through training, the model can predict the best combination of data transmission compression rate and encryption strength based on real-time monitoring data.
[0111] In actual applications, the adaptive adjustment model dynamically calculates the best parameter combination by collecting network delay, bandwidth occupancy and packet loss rate data in real time. For example, if the current network delay is 100ms, the bandwidth occupancy is 70%, and the packet loss rate is 5%, the model finally calculates the best compression rate to be 60% and the best encryption strength to be AES-128. This combination can maximize transmission efficiency while ensuring data security. The dynamic adjustment process of the model is achieved through a feedback control mechanism, that is, the parameters are further optimized based on the adjusted performance. For example, if the adjusted network delay is still high, the model may further reduce the compression rate or encryption strength to optimize transmission efficiency.
[0112] The adaptive adjustment model can automatically adjust parameters according to different network conditions and business needs to achieve the best performance of the data flow path. For example, when the network bandwidth is tight during peak hours, the model may tend to increase the compression rate to reduce the amount of data; when the network bandwidth is sufficient during off-peak hours, the model may tend to reduce the compression rate to increase the transmission speed. For encryption strength, the model can dynamically adjust the encryption level according to the sensitivity of the data and network security. For example, for highly sensitive data, the model may choose AES-256 encryption; for ordinary sensitive data, the model may choose AES-128 encryption. Through the adaptive adjustment model, the iPaaS module can realize the intelligent management of data flow paths in complex and changing network environments to ensure the optimal balance between data security and transmission efficiency.
[0113] The adaptive adjustment model in this embodiment dynamically calculates the optimal data transmission compression rate and encryption strength combination based on network delay, bandwidth occupancy rate and packet loss rate, ensuring the optimal balance between security and transmission efficiency in the data flow path. The construction and training process of the model is implemented through machine learning methods, which enables it to automatically adjust parameters and optimize system performance based on real-time monitoring data. In practical applications, the model can flexibly adjust the compression rate and encryption strength according to different network conditions and business needs to achieve intelligent management of data flow paths. It not only solves the problem of difficulty in balancing security and efficiency in traditional data flow, but also significantly improves the efficiency and security of data flow through an intelligent adaptive adjustment mechanism.
[0114] In one implementation of this embodiment, the following steps are also included: S810, the data security monitoring module uploads the risk data and the encrypted key data to the blockchain network, and the blockchain network is used to verify the integrity and compliance of the risk data and the key data based on the smart contract.
[0115] In the process of data transfer and storage, it is crucial to ensure the integrity and compliance of data. Blockchain technology, with its decentralized, tamper-proof, transparent and traceable characteristics, can safely verify data integrity and compliance. The data security monitoring module uploads risk data and encrypted key data to the blockchain network, and uses the blockchain's smart contract mechanism to verify and record the data. The blockchain network consists of multiple nodes, each of which stores a complete copy of the data. Any modification of the data requires the consensus of the majority of nodes, thereby ensuring the immutability of the data. Smart contracts are program codes running on the blockchain that can automatically execute predefined rules and logic. Through smart contracts, the blockchain network can automatically verify the integrity and compliance of uploaded data and record the verification results.
[0116] The process of uploading risk data and encrypted key data first packages the data into blockchain transactions through the data security monitoring module. Each transaction contains metadata such as the hash value of the data, timestamp, and uploader information. The hash value is a fixed-length string calculated by a hash function (such as SHA-256) that can uniquely identify the data content. The timestamp is used to record the time when the data was uploaded, and the uploader information is used to identify the source of the data. The packaged transaction is broadcast through the nodes of the blockchain network, waiting for verification and confirmation. The nodes of the blockchain network verify the transaction through a consensus mechanism (such as PoW or PoS) to ensure the authenticity and integrity of the data. After verification, the transaction is packaged into a block and added to the blockchain, becoming an unalterable record.
[0117] Smart contracts automatically verify the integrity and compliance of uploaded data through predefined rules and logic. For example, for risk data, smart contracts can verify whether its risk level meets the preset standards and whether the data content is complete; for encrypted key data, smart contracts can verify whether its encryption method meets security requirements and whether the data content is compliant. The verification process first parses the transaction data to extract its metadata such as hash value, timestamp, and uploader information. Then, the smart contract verifies the data according to predefined rules. For example, the hash value of the data is recalculated using a hash function and compared with the hash value in the transaction to ensure that the data content has not been tampered with; check whether the timestamp is within the valid range to ensure that the data upload time meets the requirements; verify whether the uploader information is legal and ensure that the data source is credible. The verification results are recorded in the blockchain through smart contracts and become tamper-proof evidence.
[0118] In actual implementation, public chain, consortium chain and private chain are three common types of blockchain. Public chain is open to all users and has the highest degree of decentralization, but has lower performance and privacy; consortium chain is jointly maintained by multiple organizations, has a higher degree of decentralization and better performance, and is suitable for data sharing between enterprises; private chain is maintained by a single organization, has the highest performance and privacy, and is suitable for internal data management of enterprises. You can choose the appropriate blockchain type according to specific needs. For example, for cross-enterprise data sharing, you can choose consortium chain; for internal data management of enterprises, you can choose private chain.
[0119] This implementation method can ensure the integrity and compliance of data by uploading risk data and encrypted key data to the blockchain network and verifying them using smart contracts. The immutability and transparent traceability of blockchain ensure that any modification to the data will be recorded and discovered, thereby enhancing data security. The automatic execution and predefined rules of smart contracts make the data verification process efficient and reliable, reducing human intervention and errors. It not only solves the problem of data integrity and compliance being difficult to ensure in traditional data management, but also significantly improves the security and credibility of data through the introduction of blockchain and smart contracts.
[0120] The present application also provides an electronic device, including: a memory configured to store instructions; and The processor is configured to call instructions from the memory and implement the above-mentioned integrated platform data flow method when executing the instructions.
[0121] In this embodiment, the electronic device can be a tablet computer, a desktop computer, a laptop computer, a handheld computer, a wearable device, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or other device with a processor. Of course, the electronic device can also be a server. The embodiment of the present application does not impose any special restrictions on the specific form of the electronic device.
[0122] The embodiment of the present application also provides a financial and taxation integrated platform, which is deployed in the above-mentioned electronic device and is used to execute the operating steps of the data flow method of the integrated platform.
[0123] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0124] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram and the combination of the processes and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0125] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0126] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0127] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0128] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0129] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0130] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0131] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A data transfer method for an integrated platform, characterized in that: Applied to the finance and taxation integration platform, the finance and taxation integration platform is obtained by integrating n business processing platforms. The finance and taxation integration platform includes an RPA module, a CL module, an iPaaS module and a data security monitoring module. The method includes: The RPA module responds to the multi-source data entry instruction, converts the multi-source data into structured data, and identifies the financial information in the structured data; The RPA module classifies and sorts the financial information and determines the processing order of the classified and sorted financial information; The CL module analyzes the financial information according to the processing sequence, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy; The iPaaS module receives risk data and key data, and transfers the risk data and key data to the data security monitoring module; The data security monitoring module uses a first processing strategy to conduct risk screening on risk data, and uses a second processing strategy to encrypt key data; and The data security monitoring module transfers risk data and encrypted key data to the corresponding business processing platform.
2. The method according to claim 1, characterized in that The CL module generates a first processing strategy and a second processing strategy, including: The CL module extracts contextual features of financial information and obtains historical data; The CL module dynamically generates a first processing strategy and a second processing strategy based on context features and historical data; The first processing strategy includes a risk data classification mechanism, a risk assessment model, an abnormal data identification rule and a risk data tracing mechanism. The risk data classification mechanism is used to determine the risk level of risk data. The risk assessment model is used to determine the risk probability of risk data according to the risk level of risk data. The abnormal data identification rule is used to determine the abnormal data in risk data according to the risk probability. The risk data tracing mechanism is used to record the processing flow of risk data. The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy and data desensitization processing rules. The hierarchical encryption strategy is used to determine the sensitivity of key data and determine the corresponding encryption algorithm based on the sensitivity. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a dispersed manner. The access permission control strategy is used to set data access permissions. The data desensitization processing rules are used to mask or replace sensitive fields in key data.
3. The method according to claim 2, characterized in that The CL module dynamically generates a first processing strategy and a second processing strategy based on context features and historical data, including: The CL module inputs data features and context features as input parameters into the pre-built machine learning model to analyze and obtain the historical processing records of risk data and the historical encryption records of key data; The CL module determines the parameters and conditions of the first processing strategy based on the historical processing records, and applies the parameters and conditions of the first processing strategy to the first processing strategy, wherein the parameters and conditions of the first processing strategy include the threshold parameters of the risk data classification mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rules, and the record items of the risk data tracing mechanism; The CL module determines the parameters and conditions of the second processing strategy based on the historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy, wherein the parameters and conditions of the second processing strategy include the encryption strength of the hierarchical encryption strategy, the key update cycle of the dynamic key management mechanism, the permission matrix of the access permission control strategy, and the desensitization method of the data desensitization processing rules.
4. The method according to claim 1, characterized in that: The RPA module sorts and categorizes the financial information and determines the order in which the sorted financial information should be processed, including: The RPA module divides the financial information based on preset data categories to obtain at least one financial data set; The RPA module determines the correlation between each financial data set and other financial data sets, and merges the financial data sets with higher correlation than a preset correlation to obtain at least one correlated financial data set; For any associated financial data set, the RPA module uses preset scoring rules to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set, where the total score is the sum of the time sensitivity score and the data value score. The order of the total scores from high to low is used as the processing order of the associated financial data sets.
5. The method according to claim 4, characterized in that The CL module includes the basic data layer, business logic layer and risk control layer. The CL module determines the risk data and key data of financial information, including: For each associated financial data set, at the basic data layer, the CL module performs format verification on the associated financial data set and treats the data in the associated financial data set that fails the format verification as risk data; At the business logic layer, the CL module verifies the business logic consistency of the associated financial data set, and treats the data in the associated financial data set that fails the business logic consistency verification as risk data; At the risk control layer, the CL module performs data sensitivity verification on the associated financial data set and regards the data in the associated financial data set that fails the data sensitivity verification as key data.
6. The method according to claim 1, characterized in that After the iPaaS module receives risk data and key data, it also includes: The iPaaS module extracts the first feature of the risk data and the second feature of the key data, and determines the optimal data flow path based on the first feature and the second feature; The iPaaS module monitors the efficiency and quality of the optimal data flow path in real time; The iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path.
7. The method according to claim 6, characterized in that The efficiency of the optimal data flow path is characterized by network latency and bandwidth occupancy, and the quality of the optimal data flow path is characterized by the packet loss rate. The iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data flow path based on the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path, including: The iPaaS module uses a pre-built adaptive adjustment model to calculate the optimal combination of data transmission compression rate and encryption strength based on network latency, bandwidth occupancy, and packet loss rate to balance data security and transmission efficiency of the optimal data flow path.
8. The method according to claim 1, characterized in that: The method also includes: The data security monitoring module uploads risk data and encrypted key data to the blockchain network, which is used to verify the integrity and compliance of risk data and key data based on smart contracts.
9. An electronic device, characterized in that: include: a memory configured to store instructions; as well as The processor is configured to call the instruction from the memory and implement the data flow method of the integrated platform according to any one of claims 1 to 8 when executing the instruction.
10. A finance and taxation integrated platform, characterized in that: The financial and taxation integration platform is deployed in the electronic device described in claim 9, and is used to execute the operation steps of any method described in claims 1-8 above.
Citation Information
Patent Citations
Financial management system and financial management method
CN116579868A
Automatic early warning method and system for enterprise financial data
CN117522136A
Financial data full-process management platform based on digitization
CN117934186A
Enterprise financial document integrated digital management system based on artificial intelligence
CN118863814A
Alternative asset based financial management contracts
US20230169594A1
Cited By
Transformer substation real-time communication encryption method and system
CN119675915A
Enterprise project management method and system based on multi-source heterogeneous data integration
CN120374060A
Comprehensive financial auditing system based on big data
CN120430879A
Electronic purchase approval method based on zero-trust model
CN120763976A
Cross-government affair system data processing method and device based on RPA, equipment and storage medium
CN120849497A